Coordinating Adobe Experience Manager security patch deployment

This article provides guidance for Adobe Experience Manager administrators on how to plan and coordinate the deployment of a security patch to address a newly identified vulnerability.

Description description

A new security vulnerability has been identified in Adobe Experience Manager (AEM), and a corresponding security patch has been released. Administrators are responsible for organizing and scheduling the patch deployment across non-production and production environments. The patching process requires operating system reboots, resulting in brief downtime for the author and publish tiers. To minimize end-user impact, it is recommended to schedule patching and reboots outside of standard business hours and to update environments in a rolling fashion. No specific error messages or stack traces are associated with this proactive security update.

Environment

Adobe Experience Manager (all versions)

Symptoms

No immediate symptoms; this is a proactive security update to address vulnerabilities.

Cause

A security vulnerability identified in AEM requires a patch to maintain system security and compliance.

Resolution resolution

Follow the steps below to resolve the issue.

  1. Review the details of the relevant Adobe Experience Manager security bulletin to understand the vulnerabilities addressed and the recommended patching procedures.
  2. Plan the patch deployment for both non-production and production environments according to your organization’s change management processes.
  3. Notify all relevant stakeholders about the planned downtime due to required operating system reboots during the patching process.
  4. Schedule patching and reboots outside of standard business hours when possible to minimize end-user impact.
  5. Update author and publish tiers in a rolling fashion to further reduce downtime for end users.
  6. If using automation for patch deployment, note that the exact timing of reboots may vary, but efforts should be made to perform them during low-traffic periods.
  7. If manual patching is preferred, coordinate with your internal teams to schedule the update during an approved maintenance window.
  8. After patching, monitor all environments to ensure that services are running as expected and verify that the patch has been successfully applied.
recommendation-more-help
experience-cloud-kcs-help-kbarticles